Skip to content

This website does not advertise or solicit work, consistent with the Bar Council of India's rules for advocates. Continued use confirms you are seeking this information at your own request and that it does not create a lawyer–client relationship. Read the full disclaimer.

Sagar & Sagar Law Offices

Technology, AI, Data Privacy & Cybersecurity

Technology and data practice concerns the legal framework applicable to digital products, platforms and infrastructure, the processing of personal data, and the response to cyber incidents. Sagar & Sagar Law Offices advises on obligations under the Digital Personal Data Protection Act, 2023 and the Information Technology Act, 2000, drafts and negotiates technology and data processing contracts, advises on artificial intelligence deployment and governance, and represents businesses in regulatory proceedings and in disputes arising from technology arrangements. Work spans preventive compliance, transactional documentation and incident response.


Overview

India's technology regulation has moved from a single statute to a layered framework. The Information Technology Act, 2000 continues to govern electronic records, offences and intermediary obligations; the Digital Personal Data Protection Act, 2023 establishes a consent-based regime for personal data with its own regulator; sectoral regulators impose their own cyber security and data requirements on regulated entities; and directions issued to computer resource operators impose incident reporting obligations independent of all of these. A single technology business will typically be subject to several of these at once.

The practice at Sagar & Sagar Law Offices covers this framework as it applies to products, contracts and incidents. Work includes data protection compliance programmes and documentation, technology contracting across procurement and supply, advice on platform and intermediary obligations, governance advice on artificial intelligence deployment, and legal support during and after a cyber incident. Where a technology matter involves intellectual property or content regulation, it is conducted with the firm's Intellectual Property and Media practices.


Scope of work

Data protection compliance

Obligations concerning the processing of personal data.

  • Advice on the application of the Digital Personal Data Protection Act, 2023 to a business and its processing activities
  • Data mapping and assessment of processing activities against statutory obligations
  • Advice on the lawful basis for processing and on the consent architecture required
  • Drafting of privacy notices and consent language
  • Advice on purpose limitation, data minimisation and retention
  • Advice on rights of data principals and on mechanisms for exercising them
  • Advice on obligations applicable to significant data fiduciaries, where notified as such
  • Advice on engagement of data processors and on the contractual terms required
  • Advice on cross-border transfer of personal data
  • Internal data protection policies, standard operating procedures and training material
  • Advice on obligations concerning the personal data of children
  • Advice on the interaction between data protection obligations and sectoral regulatory requirements

Cyber incident response and cybersecurity

Legal work before, during and after a security incident.

  • Advice on incident reporting obligations, including directions applicable to computer resource operators
  • Advice on notification obligations to regulators, data principals and counterparties
  • Legal support during incident response, including preservation of evidence and privilege
  • Advice on log retention and record-keeping obligations
  • Advice on regulatory follow-up and inquiry arising from an incident
  • Advice on contractual liability and indemnity positions arising from incidents affecting vendors or customers
  • Advice on ransomware and extortion situations and the legal constraints applicable
  • Advice on cyber security requirements imposed on regulated entities by sectoral regulators
  • Incident response plans, escalation protocols and tabletop documentation
  • Advice on obligations relating to critical information infrastructure, where applicable

Intermediary, platform and content obligations

Obligations of entities hosting or transmitting third-party content.

  • Advice on availability of and conditions attaching to safe harbour for intermediaries
  • Advice on due diligence obligations under the applicable intermediary rules
  • Advice on grievance redressal mechanisms and officer appointment requirements
  • Advice on takedown obligations and on responses to takedown requests
  • Advice on responses to requests and orders from government authorities
  • Advice on obligations relating to traceability and information requests, where applicable
  • Advice on user terms, community standards and acceptable use policies
  • Advice on obligations of significant social media intermediaries, where applicable
  • Advice on obligations applicable to online gaming and to the regulatory framework governing it
  • Representation in proceedings arising from content and platform obligations

Artificial intelligence

Legal and governance work concerning the development and deployment of AI systems.

  • Advice on the legal framework applicable to AI deployment in India
  • Advice on the interaction between AI systems and data protection obligations
  • Advice on training data, its sourcing and the rights required in respect of it
  • Advice on ownership of and rights in AI-generated output
  • Advice on allocation of liability for AI system outputs in commercial contracts
  • Drafting of AI procurement, development and deployment agreements
  • Advice on AI governance frameworks, internal policies and human oversight arrangements
  • Advice on transparency, disclosure and labelling of AI-generated content
  • Advice on sector-specific constraints on automated decision-making
  • Advice on synthetic media, deepfakes and associated exposure
  • Contractual and regulatory advice for businesses embedding third-party AI services

Technology contracting

Documentation through which technology is procured and supplied.

  • Drafting and negotiation of software licensing agreements
  • Drafting and negotiation of software as a service and subscription agreements
  • Cloud services agreements and advice on data location and access terms
  • Master services agreements and statements of work
  • Technology development and implementation agreements
  • Information technology outsourcing and managed services agreements
  • Data processing agreements and data sharing arrangements
  • Service level agreements, credits and remedies for failure
  • Source code escrow arrangements
  • Advice on open source licensing and compliance
  • Reseller, distributor and channel partner agreements
  • Advice on limitation of liability, indemnity and allocation of risk in technology contracts
  • Technology and data due diligence in transactions

Electronic commerce and digital business

Regulation of commerce conducted through digital channels.

  • Advice on obligations applicable to electronic commerce entities and marketplaces
  • Advice on seller onboarding, listing and liability allocation
  • Advice on consumer disclosure, pricing and cancellation requirements
  • Advice on returns, refunds and grievance handling obligations
  • Website and application terms of use and customer-facing documentation
  • Advice on advertising, endorsement and disclosure obligations in digital channels
  • Advice on payment integration and its regulatory requirements
  • Advice on digital contracting, electronic signatures and record retention

Telecommunications and digital infrastructure

Regulation of communications services and networks.

  • Advice on the framework applicable to telecommunication services and networks
  • Advice on authorisation and licensing requirements
  • Advice on obligations imposed on service providers, including in relation to interception and security
  • Advice on regulatory proceedings before the sectoral regulator
  • Representation before the telecom disputes appellate tribunal
  • Advice on infrastructure sharing and interconnection arrangements

Technology disputes and cybercrime

Contentious work arising from technology arrangements and misuse.

  • Disputes arising from technology contracts, including implementation failure and termination
  • Disputes concerning data, access and confidential information
  • Advice and complaints in respect of cyber fraud, unauthorised access and data theft
  • Representation in proceedings concerning offences under the Information Technology Act, 2000
  • Advice on preservation and admissibility of electronic evidence
  • Injunctive relief in respect of misuse of data or systems
  • Advice on employee misconduct involving systems and data
  • Coordination where a cyber incident gives rise to financial crime exposure

Forums and authorities

  • Data Protection Board constituted under the Digital Personal Data Protection Act, 2023
  • Ministry of Electronics and Information Technology
  • Indian Computer Emergency Response Team, in respect of incident reporting
  • Adjudicating officers appointed under the Information Technology Act, 2000
  • Sectoral regulators imposing cyber security and data requirements
  • Telecom Regulatory Authority of India and the Telecom Disputes Settlement and Appellate Tribunal
  • Central Consumer Protection Authority, in respect of digital commerce
  • Cyber crime investigation units and police authorities
  • Commercial Courts and Commercial Divisions, in technology contract disputes
  • High Courts and the Supreme Court of India

Who we act for

  • Technology and software companies
  • Platforms, marketplaces and intermediaries
  • Financial services entities in respect of their technology and data obligations
  • Enterprises procuring technology and outsourcing services
  • Startups and early stage technology businesses
  • Businesses deploying artificial intelligence systems
  • Data fiduciaries and data processors
  • Telecommunications and infrastructure providers
  • Entities responding to cyber incidents

How we approach this work

Obligations identified across frameworks, not within one.

A technology business is usually subject to general data protection law, information technology law, sectoral regulation and contractual obligation at once. Advice establishes the full set before addressing any single requirement.

Compliance built into the product, not appended to it.

Consent architecture, notices and retention are addressed at the design stage, since retrofitting them into a live product is materially harder.

Incident response planned in advance.

Reporting timelines in cyber incidents are short. Obligations, escalation paths and evidence preservation protocols are settled before an incident rather than during one.

Contractual risk allocated deliberately.

Liability, indemnity and service level provisions in technology contracts are negotiated by reference to the actual failure modes of the arrangement rather than to standard positions.


Frequently asked questions

Who must comply with the Digital Personal Data Protection Act, 2023?
The Act applies to the processing of digital personal data within India, and to processing outside India where it is in connection with the offering of goods or services to data principals within India, subject to the exemptions in the Act. Obligations fall principally on data fiduciaries, who determine the purpose and means of processing, with processors acting under contract with them.
What is the difference between a data fiduciary and a data processor?
A data fiduciary determines the purpose and means of processing personal data and bears the principal statutory obligations, including in relation to notice, consent, security and breach intimation. A data processor processes personal data on behalf of a data fiduciary under a contract. The distinction is determined by function rather than by the label used in an agreement.
What are the obligations following a personal data breach?
The Digital Personal Data Protection Act, 2023 requires a data fiduciary to give intimation of a personal data breach in the manner and to the persons specified under the Act and the rules framed under it. Separate incident reporting obligations may apply under directions issued to computer resource operators, and sectoral regulators may impose their own reporting requirements on regulated entities. The obligations operate independently and should be assessed together.
What is safe harbour for intermediaries?
The Information Technology Act, 2000 provides that an intermediary is not liable for third-party information hosted or transmitted by it, subject to the conditions in that provision and to observance of the due diligence prescribed by the applicable rules. The protection is conditional, and failure to observe the prescribed due diligence or to act upon a valid order may result in its loss.
Is there a dedicated law regulating artificial intelligence in India?
India does not presently have a single dedicated statute governing artificial intelligence. AI deployment is regulated through existing frameworks, including data protection law, information technology law, sectoral regulation, consumer protection and contract, together with advisories issued from time to time. The position is developing, and businesses deploying AI should assess exposure across those frameworks rather than await a single instrument.
Who owns the output generated by an AI system?
Ownership of AI-generated output is not settled by dedicated statutory provision in India, and existing copyright law contemplates authorship in terms that do not map straightforwardly onto machine-generated material. In practice, allocation is addressed contractually between the parties to a development or deployment arrangement. The position on training data and on inputs is addressed separately.
What should a company do first after a cyber incident?
The immediate legal considerations are preservation of evidence and logs, assessment of reporting obligations and their timelines, identification of the personal data affected, and management of communications so that privilege is not inadvertently lost. Reporting timelines under the applicable directions can be short, which is why obligations are ordinarily mapped before an incident occurs.
What should a data processing agreement contain?
A data processing agreement ordinarily records the scope, purpose and duration of processing, the categories of data and data principals, restrictions on further processing and sub-processing, security obligations, assistance with data principal requests, breach notification, audit rights, and obligations on deletion or return of data. Terms should reflect the statutory obligations of the fiduciary, which cannot be discharged by contract alone.



For enquiries relating to this practice area, please use the details on the Contact page.